30 likes | 35 Views
It has always been difficult to pass Professional-Cloud-Security-Engineer exam without a proper preparation from a reliable study material. Professional-Cloud-Security-Engineer dumps is the only material that can help you pass your IT exam by the first attempt. This study guide is in PDF format and is short and handy. You can download it from PassExam4Sure at very reasonable price with money back guarantee. This guarantee assures you to return your money back in case of your failure in the exam but it is impossible if you study from Professional-Cloud-Security-Engineer dumps sincerely.
E N D
Google PROFESSIONAL -CLOUD-SECURITY -ENGINEER Ex am Cloud Certified - Professional Cloud Security Engineer Questions & Answers Demo https://www.passexam4sure.com/google/professional-cloud-security-engineer-dumps.html
Questions&AnswersPDF Page2 Version:10.0 Question:1 YourteamneedstomakesurethataComputeEngineinstancedoesnothaveaccesstotheinternetorto anyGoogleAPIsorservices. Whichtwosettingsmustremaindisabledtomeettheserequirements?(Choosetwo.) A.PublicIP B.IPForwarding C.PrivateGoogleAccess D.Staticroutes E.IAMNetworkUserRole Answer:AC Explanation: Reference:https://cloud.google.com/vpc/docs/configure-private-google-access Question:2 WhichtwoimpliedfirewallrulesaredefinedonaVPCnetwork?(Choosetwo.) A.Arulethatallowsalloutboundconnections B.Arulethatdeniesallinboundconnections C.Arulethatblocksallinboundport25connections D.Arulethatblocksalloutboundconnections E.Arulethatallowsallinboundport80connections Answer:AB Explanation: Reference:https://cloud.google.com/vpc/docs/firewalls Question:3 Acustomerneedsanalternativetostoringtheirplaintextsecretsintheirsource-codemanagement (SCM)system. HowshouldthecustomerachievethisusingGoogleCloudPlatform?
Questions&AnswersPDF Page3 A.UseCloudSourceRepositories,andstoresecretsinCloudSQL. B. EncryptthesecretswithaCustomer-ManagedEncryptionKey(CMEK), Storage. C.RuntheCloudDataLossPreventionAPItoscanthesecrets,andstoretheminCloudSQL. D.DeploytheSCMtoaComputeEngineVMwithlocalSSDs,andenablepreemptibleVMs. andstoretheminCloud Answer:B Explanation: Question:4 YourteamwantstocentrallymanageGCPIAMpermissionsfromtheiron-premisesActiveDirectory Service.YourteamwantstomanagepermissionsbyADgroupmembership. Whatshouldyourteamdotomeettheserequirements? A.SetupCloudDirectorySynctosyncgroups,andsetIAMpermissionsonthegroups. B.SetupSAML2.0SingleSign-On(SSO),andassignIAMpermissionstothegroups. C. UsetheCloudIdentityandAccessManagementAPI ActiveDirectory. D.UsetheAdminSDKtocreategroupsandassignIAMpermissionsfromActiveDirectory. tocreategroupsandIAMpermissionsfrom Answer:B Explanation: Reference: management-system-with-google-cloud-platform https://cloud.google.com/blog/products/identity-security/using-your-existing-identity- Question:5 Whencreatingasecurecontainerimage, possible?(Choosetwo.) whichtwoitemsshouldyouincorporateintothebuildif A.EnsurethattheappdoesnotrunasPID1. B.Packageasingleappasacontainer. C.Removeanyunnecessarytoolsnotneededbytheapp. D.Usepubliccontainerimagesasabaseimagefortheapp. E.Usemanycontainerimagelayerstohidesensitiveinformation. Answer:BC Explanation: Reference:https://cloud.google.com/solutions/best-practices-for-building-containers